Terminology Index
Glossary
2953 terms
A32
Attack Surface Reduction
Shrinking the number of ways an attacker could get in by removing or disabling unnecessary services, features, accounts, and exposure, so there is simply less to attack and defend.
Every running service, open port, or extra account is a potential entry point, and reduction removes the ones that are not needed. It is a foundational hardening principle that lowers risk cheaply and creates a cost asymmetry, making the attacker's job harder while simplifying the defender's.
Introduced in: System Hardening Fundamentals
Examples
- Disabling an unused network service so it cannot be exploited.
- Removing default accounts and sample files from a server.
- Closing ports that no application requires.
Related
Configuration Baselinesrelates_toDefault Configurationsrelates_toDefense Cost Asymmetryrelates_toCIS Benchmarksrelates_toApplication Allowlistingrelates_toApplication Hardeningrelates_toAttack Surfaceprerequisite_ofBanner Disclosurerelates_toBastion Hostsrelates_toCIS Benchmarksrelates_toConfiguration Baselinesrelates_toContainer Hardeningrelates_toCVSSrelates_toDefault Configurationsrelates_toDefense Cost Asymmetryrelates_toDisk Encryptionrelates_toEmergency Patchesrelates_toEndpoint Hardeningrelates_toHardening Guidesrelates_toImage Hardeningrelates_toInternet Exposurerelates_toJump Serversrelates_toLocal Admin Restrictionrelates_toMacro Restrictionrelates_toManagement Networkrelates_toPrinciple of Least Functionalityrelates_toPrivateLinkrelates_toRisk-Based Prioritizationrelates_toScreen Lockrelates_toSecure by Defaultrelates_toService Endpointsrelates_toSNMPrelates_toSystem Hardeningrelates_to
